web-app-logic

v2026.09.24

Web application logic testing - business logic flaws, race conditions, access control, cache poisoning/deception, and information disclosure.

GitHub
安装命令
npx skhub add transilienceai/web-app-logic
Markdown
SKILL.md

Web Application Logic

Test for logic flaws and application-specific vulnerabilities that automated scanners miss.

Techniques

TypeKey Vectors
Business LogicWorkflow bypass, price manipulation, feature abuse
Race ConditionsTOCTOU, limit bypass, double-spend, parallel requests
Access ControlIDOR, horizontal/vertical privilege escalation, forced browsing
Cache PoisoningUnkeyed headers/parameters, fat GET, response splitting
Cache DeceptionPath confusion, static extension tricks, normalization
Info DisclosureError messages, debug endpoints, source code, metadata

Workflow

  1. Map application workflows and business rules
  2. Identify state-dependent operations and trust boundaries
  3. Test logic assumptions with edge cases and race conditions
  4. Verify access control across user roles
  5. Document impact with PoC demonstrations

Reference

  • reference/business-logic*.md - Business logic testing techniques
  • reference/race-conditions*.md - Race condition exploitation
  • reference/access-control*.md - Access control bypass methods
  • reference/web-cache-poisoning*.md - Cache poisoning techniques
  • reference/web-cache-deception*.md - Cache deception attacks
  • reference/information-disclosure*.md - Information disclosure testing
发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

Sep 24, 2026

分类

未分类

许可证

MIT

源路径

skills/web-app-logic

默认分支

main

最新提交

95fdc12

Tree SHA

854bd03